Description
UCMS 1.4.7 allows remote authenticated users to change the administrator password because $_COOKIE['admin_'.cookiehash] is used for arbitrary cookie values that are set and not empty.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-11128 | UCMS 1.4.7 allows remote authenticated users to change the administrator password because $_COOKIE['admin_'.cookiehash] is used for arbitrary cookie values that are set and not empty. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T11:37:11.338Z
Reserved: 2018-11-21T00:00:00.000Z
Link: CVE-2018-19437
No data.
Status : Modified
Published: 2018-11-22T05:29:01.200
Modified: 2024-11-21T03:57:55.017
Link: CVE-2018-19437
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD